launchdarkly-server-sdk is vulnerable to Information Disclosure
53
Medium Risk
The migration op event serializer inlined the raw evaluation context instead of the redacted context view used by every other inline event type. When an application records migration operation metrics for contexts that declare private attributes, are covered by globally configured private attributes, or run with all-attributes-private mode, those private attribute values are serialized in plaintext into the outbound migration_op analytics payload. Private data the application explicitly marked as private therefore leaves the SDK even though it is redacted in ordinary events. The fix routes the migration context through the same shared ContextAttributes redaction path as BaseEvent so private attributes are stripped before events are sent.
You are affected if you are using a version that falls within the vulnerable range and your application records migration operation events for contexts that use private attributes.
launchdarkly-server-sdk is vulnerable to Information Disclosure in versions 2.6.0 - 3.1.1.
Upgrade the launchdarkly-server-sdk library to the patch version.
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant